centos 7 and window 7 ulti

soulofangel

Member
Joined
Feb 9, 2013
Messages
234
Reaction score
0
I have a game server running on window 7 ulti.
and a centos which is serving the database.

how do i encrypt the traffic( or config it) such that people cannot decrypt the user/pass sent across?



Thanks
 

davidktw

Arch-Supremacy Member
Joined
Apr 15, 2010
Messages
13,551
Reaction score
1,302
I have a game server running on window 7 ulti.
and a centos which is serving the database.

how do i encrypt the traffic( or config it) such that people cannot decrypt the user/pass sent across?

Thanks

I will assume you are using MySQL. MySQL supports SSL connections. You can read up more at MySQL :: MySQL 5.0 Reference Manual :: 6.3.6.3 Using SSL Connections and Setting up MySQL SSL and secure connections

There are other secure approaches like setting up a VPN in your Linux system or using socat.

If not one extremely easy approach is port forward using SSH like this. On windows, you can try using N2 - MyEnTunnel - A background SSH tunnel daemon or http://www.coretechnologies.com/products/AlwaysUp/Apps/RunPuTTYAsAService.html

The idea is create a local port forwarding to local port 3306 (for mysql) or other ports depending on what tcp port your database is running on, via SSH.

If I have a unix client SSH client, the command will be
Code:
ssh -NC -L3306:localhost:3306 user@linux-server
On the client, you can connect to localhost:3306 and it will be forwarded to the server.
 
Last edited:

soulofangel

Member
Joined
Feb 9, 2013
Messages
234
Reaction score
0
Ok, i setup the mysql SSL. How do i get window server to use the ssl? Its working when i remove the "require ssl".

Do i need to generate the certs in my windows too?
 
Last edited:

davidktw

Arch-Supremacy Member
Joined
Apr 15, 2010
Messages
13,551
Reaction score
1,302
Ok, i setup the mysql SSL. How do i get window server to use the ssl? Its working when i remove the "require ssl".

Do i need to generate the certs in my windows too?

No you do not need client certificate unless you also grant REQUIRE X509 for the specific user. REQUIRE SSL only requires the client to establish an SSL connection to the server without client authentication via certs

Did you use self-signed certs or private CA signed certs for your MySQL server. You will need to copy the self-signed cert or private CA public cert to the Windows client for verification of the MySQL server cert.

Are you using ODBC or JDBC for your application to connect to the MySQL server ? The first, you can read up MySQL connection using ODBC (5.1) with SSL - Stack Overflow, the latter, MySQL :: MySQL Connector/J Developer Guide :: 5.5 Connecting Securely Using SSL
 

soulofangel

Member
Joined
Feb 9, 2013
Messages
234
Reaction score
0
I generated my cert using this: MySQL :: MySQL 5.5 Reference Manual :: 6.3.9.5 Setting Up SSL Certificates and Keys for MySQL

MariaDB [(none)]> show variables like '%ssl%';
+---------------+--------------------------------+
| Variable_name | Value |
+---------------+--------------------------------+
| have_openssl | YES |
| have_ssl | YES |
| ssl_ca | /etc/mysql-ssl/ca-cert.pem |
| ssl_capath | |
| ssl_cert | /etc/mysql-ssl/server-cert.pem |
| ssl_cipher | |
| ssl_key | /etc/mysql-ssl/server-key.pem |


And i added the CA-cert into my window7 certmgr.msc > trusted root CA

but i am still getting access denied. any idea where is the problem?
 

davidktw

Arch-Supremacy Member
Joined
Apr 15, 2010
Messages
13,551
Reaction score
1,302
I generated my cert using this: MySQL :: MySQL 5.5 Reference Manual :: 6.3.9.5 Setting Up SSL Certificates and Keys for MySQL

MariaDB [(none)]> show variables like '%ssl%';
+---------------+--------------------------------+
| Variable_name | Value |
+---------------+--------------------------------+
| have_openssl | YES |
| have_ssl | YES |
| ssl_ca | /etc/mysql-ssl/ca-cert.pem |
| ssl_capath | |
| ssl_cert | /etc/mysql-ssl/server-cert.pem |
| ssl_cipher | |
| ssl_key | /etc/mysql-ssl/server-key.pem |


And i added the CA-cert into my window7 certmgr.msc > trusted root CA

but i am still getting access denied. any idea where is the problem?

Before you proceed to connect from your Windows, can you connect via the mysql command line utility from the server using the server's network facing IP Address ?

EG:
Code:
mysql -u <USERID> -p -h <NETWORK IP> --ssl-ca=/path/to/ca-cert.pem

I'm not sure placing the CA cert into your Windows trust store works. I doubt the ODBC connector is consulting the OS truststore since there is a field as shown in MySQL connection using ODBC (5.1) with SSL - Stack Overflow where the SSL certificate has to be explicitly specified

Can you confirm whether you can connect via the command line first before connecting from a Windows system ?
 

soulofangel

Member
Joined
Feb 9, 2013
Messages
234
Reaction score
0
my.cnf
[mysqld]
port = 33006 (customized port)
bind-address =192.168.1.X (db server)
#skip-networking

mysql -u <USERID> -p -h <NETWORK IP> --ssl-ca=/path/to/ca-cert.pem

result in error:
ERROR 2003 (HY000): Can't connect to MySQL server on '192.168.1.18' (113)

it is already granted all in mysql:
GRANT ALL ON `db_test`.* TO 'user1'@'%' require ssl;

i can login user1 if i don't specify -h
and when i type
status;
SSL: Cipher in use is DHE-RSA-AES256-GCM-SHA384



all cert owners belong to mysql:mysql

is it my bind-address problem?
or firewall? firewall-cmd --zone=private --add-port=33006/tcp --permanent
 
Last edited:

davidktw

Arch-Supremacy Member
Joined
Apr 15, 2010
Messages
13,551
Reaction score
1,302
my.cnf
[mysqld]
port = 33006 (customized port)
bind-address =192.168.1.X (db server)
#skip-networking

mysql -u <USERID> -p -h <NETWORK IP> --ssl-ca=/path/to/ca-cert.pem

result in error:
ERROR 2003 (HY000): Can't connect to MySQL server on '192.168.1.18' (113)

it is already granted all in mysql:
GRANT ALL ON `db_test`.* TO 'user1'@'%' require ssl;

i can login user1 if i don't specify -h
and when i type
status;
SSL: Cipher in use is DHE-RSA-AES256-GCM-SHA384



all cert owners belong to mysql:mysql

is it my bind-address problem?
or firewall? firewall-cmd --zone=private --add-port=33006/tcp --permanent

Well from your description, it seems like your firewall is blocking external access to tcp:3306, when you are not specifying the host "-h" option in your mysql client, that means it is either using the unix socket or localhost

One simple way to know if your mysql daemon is listening on the necessary ip and port is using "netstat -pnlt | grep :3306" using root user

It will show which are the daemons currently listening on port 3306
 
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ Forums. Forum members and moderators are responsible for their own posts. Please refer to our Community Guidelines and Standards and Terms and Conditions for more information.
Top